Showing posts with label justqdjing. Show all posts
Showing posts with label justqdjing. Show all posts
Friday, 20 November 2015
五种有效的学习方法 - 方法比努力重要
1 目标学习法
掌握目标学习法是美国心理学家布卢姆所倡导的。布卢姆认为只要有最佳的教学,给学生以足够的时间,多数学习者都能取得优良的学习成绩。
教 学内容是由许多知识点构成,由点形成线,由线完成相对独立的知识体系,构成彼此联系的知识网。因此明确目标,就要在上新课时了解本课知识点在知识网中的 位置,在复习时着重从宏观中把握微观,注重知识点的联系。另外,要明确知识点的难易程度,应该掌握的层次要求,即识记、理解、应用、分析、综合、评价等不 同层次,最重要的就是明确学习重要目标,即知识重点。有了目标能增强我们学习的注意力与学习动机,即为了这目标我必须好好学习。
可见,明确学习目标是目标学习法的先决条件。目标学习法的核心问题,是必须形成自我测验、自我矫正,自我补救的自我约束习惯。对应教学目标编制形成性检测题,对自己进行检测,并及时地反馈评价,及时矫正和补救。
学 习目标与人生目标不同,它比较具体,可以在短时间内实现。它可以使我们比较容易地享受成功的欢乐。增加我们的信心。因此,目标学习法也是成功教育的主要 策略之一,同时,实现学习目标也是实现人生目标的开始,只有使大小、远近目标有机的结合,才会避免一些无效劳动的发生。
2 问题学习法
带着问题去看书,有利于集中注意力,目的明确,这既是有意学习的要求,也是发现学习的必要条件。心理学家把注意分为无意注意与有意注意两种。有意注意要求 预先有自觉的目的,必要时需经过意志努力,主动地对一定的事物发生注意。它表明人的心理活动的主体性和积极性。问题学习法就是强调有意注意有关解决问题的 信息,使学习有了明确的指向性,从而提高学习效率。
问题学习法要求我们看书前,首先去看一下课文后的思考题,一边看书一边思考;同时,它还要求我们在预习时去寻找问题,以便在听课时在老师讲解该问题时集中注意力听讲;最后,在练习时努力地去解决一个个问题,不要被问题吓倒,解决问题的过程就是你进步的过程。
3 矛盾学习法
矛盾的观点是我们采用对比学习法的哲学依据因为我们要进行对比,首先要看对比双方是否具有相似、相近、或相对的属性,这就是可比性。对比法的最大优点在 于:(1)对比记忆可以减轻我们记忆负担,相同的时间内可识记更多的内容。(2)对比学习有利于区别易混淆的概念、原理,加深对知识的理解。(3)对比学 习要求我们把知识按不同的特点进行归类,形成容易检索的程序知识,有利于知识的再现与提取,也有利于知识的灵活运用。
综观中学课本,可比 知识比比皆是,如政治内容中,权利与义务、民主与法制、物质与意识、和平与发展等等;如语文学习中,复句与单句、设问与反问、比喻与借 代、记叙与议论、实词与虚词等等;如数学学习中,小数与分数、指数与对数、奇函数与偶函数、平行与垂直等等;如化学学习中,金属与非金属、晶体与非晶体、 化合与分解、氧化与还原、酸与盐等等。对比学习法不仅可以用于同一学科内的学习,还可以进行跨学科比较,如学习政治可用语文中的句子分析法来分析政治概 念,如在学习近现代史中的民族解放运动时,又可以利用政治有关民族的基本观点,学习自然学时,可回忆一下有关语文课本中的有关科学家的传记文章,也可结合 唯物辩证法的有关原理进行学习。
4 联系学习法
唯物辩证法认为世界上任何事物都是同周围的事物存在着相互影响、相互制约的关系。科学知识是对客观事物的正确反映,因此,知识之间同样存在着普遍的联系,我们把联系的观点运用到学习当中,会有助于对科学知识的理解,会起到事半功倍的效果。
根 据心理学迁移理论,知识的相似性有利于迁移的产生,迁移是一种联系的表现,而联系学习法的实质不能理解为仅仅只是一种迁移。迁移从某种意义上说是自发 的,而运用联系学习法的学习是自觉的,是发挥主观能动性的充分体现,它以坚信知识点必然存在联系为首要前提,从而有目的地去回忆、检索大脑中的信息,寻找 出它们间的内在联系。当然,原来对知识掌握的广度与深度直接影响到建立知识间联系的数量多少,但我们可以通过辩证思维,通过翻书、查阅、甚至是新的学习, 去构建新的知识联系,并使之贮存在我们的大脑之中,使知识网日益扩大。这一点是迁移所不能做到的。
学习新知识就要想到旧知识,想到自己亲 身经历过的事,不能迷信权威,克服定势思维。把抽象的知识具体化,发挥右大脑的作用。如辛亥革命发生在1911年, 二次革命发生在1913年,护国战争发生在1915年,护法战争发生在1917年,这四个历史事件依次间隔二年,只要记住这两个历史事件的逻辑顺序,知道 其中任何一个事件的年代,就可以联想,推算出其它三个事件的年代。这是联想记忆法。
读书之法,既先识得他外面一个皮壳,又须识得他里面骨髓方好。——朱熹
5 归纳学习法
所谓归纳学习法是通过归纳思维,形成对知识的特点、中心、性质的识记、理解与运用。当然,作为一种学习方法来说,归纳学习法崇尚归纳思维,但它不等同于归纳思维本身,同时它还要以分析为前提。
可见,归纳学习法指的是要善于去归纳事物的特点、性质,把握句子、段落的精神实质,同时,以归纳为基础,搜索相同、相近、相反的知识,把它们放在一起进行识记与理解。其优点就在于能起到更快地记忆、理解作用。
研究必须充分地占有材料,分析它的各种发展形式,探寻这些形式的内在联系。——马克思
转载自Tetraph:
http://www.tetraph.com/blog/study/study-method/
心的回归 - 这一生,我们都走在回家的路上
这一生,我们都走在回家的路上。
回家,永远是我心中无法解开的情节。无论身在何处,我的心永远是朝着家的方向,它在一角默默的绽开,灯火阑珊处映射着家的绚丽。
家,也将是一个多么令人心痛的字眼。离家之后才明白对家是多么的不舍,张开的翅膀听到它也会微微一颤,纵然身躯多么矫健,臂膀多么宽厚,在家的面前也将是脆弱无力。
夜 深,烟花升,灯火明。多少人已经离开了家,多少人将要离开家,又有多少人想要回家。多少人在异地不经意的抬头,看见烟火绚烂的绽放,失落感油然而生,可 为了所谓的梦想,多少人无可奈何,百感交集。家里的灯火或许没那么美丽,烟花或许没那么灿烂,但是自己的内心仍能感受到家的体温,它像母亲的双手般温暖, 父亲的教导般纯朴,亲人的劝告般温馨。它流在你的血液里,扎根在你的骨髓中。它无时不刻不在提醒你,让心回家。
公益回家的广告,煽动了我 们多少泪点,也唤醒了我久已沉睡的心。父母在,不远行。直到今天我才大彻大悟,这句话说了两千年,可有多少人才能明白它的真谛? 有多少人能按照它的旨意前行?起码我不是,以前不是。我不得不悔恨自己,悔恨当初。曾经一心想飞,想离家远远的,越远越好。抛开一切,逃避束缚,为了所谓 的梦想,可怜的父母,在所谓面前低人一等,而他们没有半句怨言,依然在静静的支持你,鼓励你。背后的辛酸与泪水你看不到,你看到的只是灯红酒绿,你看到的 只是金钱与权力,你看到的只是名声与羡慕!你眼里只有你所谓的成功,只有你的片刻的掌声与欢笑。你没有看到,父母的孤独与寂寞,他们什么都不需要,只要你 的陪伴与电话!他们只想要一个完整的你,一个健康快乐的你。有时候他们只是想见你一面,想听听你的声音,这你都不能满足,又怎能谈成功?
我 欠他们的太多了,多的一辈子都无法弥补,这是一种罪,天大的罪,罄竹难书。我们太吝啬了,小气到在家就不曾说句感激的话,不曾多一些时间多陪一陪他们。 而我们呢,很忙,真的很忙。我们忙什么了?睡觉?玩电脑?玩手机?聚会?是啊,是挺忙的。我们给了他们多少时间?一日两餐吗?
内疚是失败 者 的独白,但却是良心的谴责。当车票买到手的那刻,我知道我对父母的歉疚只能加深而不能弥补了。远行,我甚至有些反感了,多少次我扪心自问,按 照这样的走法,与父母的相处机会可是真的屈指可数了。相信很多远行者都是一年回家两次,按照这个算法,我们回家的次数还能过百吗?
永远不会 忘记,我们是中国人,百善孝为先。如果我连最基本的都做不到,我就是一个一事无成的人,一个不完整的人。每次离家我都会躲避母亲的眼神,那是失 望,期望,坚定的汇总。仔细想想,我最基本的责任都没尽到,其他还有什么可谈。家,永远是我们梦境也是我们自己创造的,是我们大脑存在的凌乱的记忆碎片在 梦中被一种无形的力量加以整合与编造,使之存在短暂的真实感,并伴随着醒来渐渐消退。的港湾,心中没有家的人永远是一个失败者。
无论多久,它总会在梦中出现,不论多远,我们不会停止奔跑的脚步,朝着家的方向。将来的将来,我不再迷茫,不再没有目的的追求,不走没有结果的旅程。家,永远是我的落脚点,让心回家,回到父母身边,弥补欠下的债。
这一生,我们都走在回家的路上。
转载自蝶比翼美文:
http://diebiyi.com/articles/essay/home-back/
Labels:
Diebiyi,
essayjeans,
justqdjing,
回家,
回归,
心,
游子情思,
蝶比翼美文,
路
Wednesday, 7 October 2015
Five Important Work Suggestion - Very Useful for Success
This post is in partnership with Time. The article below was originally published at Time.com
With so much career advice floating around the interwebs, some of it is bound to be poor. Luckily we here at Levo don’t just trust the haphazardly doled-out opinions of self-appointed “leadership experts” and other dubious characters. We go straight to the top—men and women who have worked their way to massive career success — and ask them. What strategies actually worked for them? Which career buzz phrases should be ignored completely? Here are a few pieces of career advice that you should never follow.
1. “Always have a five-year plan.”
Haven’t you heard? Five-year plans are out, pivoting is in. Having tangible goals is awesome and necessary, but trying to plan out the next five years of your life is neither. The best opportunities are often those that you don’t see coming. Being too stuck to your “five-year plan” inhibits you from taking opportunities as they arise, and pivoting in new directions.
2. “Don’t be a job hopper.”
There are worse things to be. Namely, the quiet loyal workhorse who never leaves or makes the money she deserves. It’s a new economy people, job hopping is becoming the norm. These days, employees who stay in companies for longer than two years earn 50% less over their lifetimes. So yes, be gracious and respectful to each and every one of your employers, but certainly don’t stay in a position for fear of being labeled “a job hopper.”
3. “Follow the money.” / “Just do what you love and the money will follow.”
Equally bad advice, from opposite ends of the spectrum. Following the money with complete disregard for your interests is a surefire path toward a soul-sucking career doing something you hate. It may not even be the best financial move in the long term. On the other side of that coin, doing what you love with the expectation that financial success will miraculously follow is naive and ridiculous. As Kate White always says, think about where your interests and talents intersect with the greatest potential for financial success, and head toward those points of intersection.
4. “Don’t be too grabby. Let your work speak for itself.”
This is the kind of advice your Middle Eastern grandfather who owned a small business 40 years ago might give you (not from personal experience or anything). Even if it means well, it is just not true. Remember that episode of New Girl? Jess wants to be vice principal of her school: “I’m just hoping, you know in a few years, I’ll have enough experience that Dr. Foster will consider me for Vice Principal.” Coach asks, “Why don’t you just ask for it?” Jess says, “You can’t just ask for a promotion, you know, you have to earn the promotion with years of hard work.” Coach laughs. Please, don’t be Jess.
5. “Don’t waste time applying to jobs you know you won’t get.”
We just published a great piece from the Personal Branding Blog that addresses this very topic. Just because you think a particular job is a reach or you’re not the ideal fit, that doesn’t mean you shouldn’t apply. Within limits of course—don’t start applying for wedding photographer assistant positions if you want to be a pharmacist (unless you’ve always cultivated a secret passion for photography of course). Every job you apply to is an opportunity to tighten up your resume, hone your interview skills, and build confidence, which is never a waste of time.
Article From InZeed:
http://www.inzeed.com/kaleidoscope/life/work-useful-suggestion/
Labels:
Business,
essayjeans,
InZeed,
justqdjing,
Life,
Success,
work suggestion
Saturday, 20 June 2015
New York Times nytimes.com Page Design XSS Vulnerability (Almost all Article Pages Before 2013 are Affected)
The New York Times Old Articles Can Be Exploited by XSS Attacks (Almost all Article Pages Before 2013 Are Affected)
Domain:
http://www.nytimes.com/
"The New York Times (NYT) is an American daily newspaper, founded and continuously published in New York City since September 18, 1851, by the New York Times Company. It has won 114 Pulitzer Prizes, more than any other news organization. The paper's print version has the largest circulation of any metropolitan newspaper in the United States, and the second-largest circulation overall, behind The Wall Street Journal. It is ranked 39th in the world by circulation. Following industry trends, its weekday circulation has fallen to fewer than one million daily since 1990. Nicknamed for years as "The Gray Lady", The New York Times is long regarded within the industry as a national "newspaper of record". It is owned by The New York Times Company. Arthur Ochs Sulzberger, Jr., (whose family (Ochs-Sulzberger) has controlled the paper for five generations, since 1896), is both the paper's publisher and the company's chairman. Its international version, formerly the International Herald Tribune, is now called the International New York Times. The paper's motto, "All the News That's Fit to Print", appears in the upper left-hand corner of the front page." (Wikipedia)
(1) Vulnerability Description:
The New York Times has a computer cyber security problem. Hacker can exploit its users by XSS bugs.
The code program flaw occurs at New York Times’s URLs. Nytimes (short for New York Times) uses part of the URLs to construct its pages. However, it seems that Nytimes does not filter the content used for the construction at all before 2013.
Based on Nytimes’s Design, Almost all URLs before 2013 are affected (All pages of articles). In fact, all article pages that contain “PRINT” button, “SINGLE PAGE” button, “Page *” button, “NEXT PAGE” button are affected.
Nytimes changed this mechanism since 2013. It decodes the URLs sent to its server. This makes the mechanism much safer now.
However, all URLs before 2013 are still using the old mechanism. This means almost all article pages before 2013 are still vulnerable to XSS attacks. I guess the reason Nytimes does not filter URLs before is cost. It costs too much (money & human capital) to change the database of all posted articles before.
Living POCs Codes:
POC Video:
Blog Details:
(2) Vulnerability Analysis:
Take the following link as an example,
http://www.nytimes.com/2012/ 02/12/sunday-review/big-datas- impact-in-the-world.html/“>< vulnerabletoattack
It can see that for the page reflected, it contains the following codes. All of them are vulnerable.
<li class=”print”>
<a href=”/2012/02/12/sunday- review/big-datas-impact-in- the-world.html/”>< vulnerabletoattack?pagewanted= print”>Print</testtesttest? pagewanted=print”></a>
</li>
<li class=”singlePage”>
<a href=”/2012/02/12/sunday- review/big-datas-impact-in- the-world.html/”>< testtesttest?pagewanted=all”> Single Page</vulnerabletoattack? pagewanted=all”></a>
</li>
<li> <a onclick=”s_code_linktrack(‘ Article-MultiPagePageNum2′);” title=”Page 2″ href=”/2012/02/12/sunday- review/big-datas-impact-in- the-world.html/”>< vulnerabletoattack?pagewanted= 2″>2</testtesttest?pagewanted= 2″></a>
</li>
<li> <a onclick=”s_code_linktrack(‘ Article-MultiPagePageNum3′);” title=”Page 3″ href=”/2012/02/12/sunday- review/big-datas-impact-in- the-world.html/”>< vulnerabletoattack?pagewanted= 3″>3</testtesttest?pagewanted= 3″></a>
</li>
<a class=”next” onclick=”s_code_linktrack(‘ Article-MultiPage-Next’);” title=”Next Page” href=”/2012/02/12/sunday- review/big-datas-impact-in- the-world.html/”>< vulnerabletoattack?pagewanted= 2″>Next Page »</testtesttest?pagewanted=2″> </a>
(3) What is XSS?
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in Web applications. XSS enables attackers to inject client-side script into Web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same origin policy.
"Hackers are constantly experimenting with a wide repertoire of hacking techniques to compromise websites and web applications and make off with a treasure trove of sensitive data including credit card numbers, social security numbers and even medical records. Cross-site Scripting (also known as XSS or CSS) is generally believed to be one of the most common application layer hacking techniques Cross-site Scripting allows an attacker to embed malicious JavaScript, VBScript, ActiveX, HTML, or Flash into a vulnerable dynamic page to fool the user, executing the script on his machine in order to gather data. The use of XSS might compromise private information, manipulate or steal cookies, create requests that can be mistaken for those of a valid user, or execute malicious code on the end-user systems. The data is usually formatted as a hyperlink containing malicious content and which is distributed over any possible means on the internet." (Acunetix)
The vulnerability can be attacked without user login. Tests were performed on Firefox (34.0) in Ubuntu (14.04) and IE (9.0.15) in Windows 8.
Discover and Reporter:
Jing Wang, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. (@justqdjing)
More Details:
Labels:
0Day-Bugs,
Code Flaw,
computer,
Computer Exploit,
cyber intelligence,
hacker,
IEEE Research,
internet,
Internet News,
jing.wang,
justqdjing,
Nytimes.com,
The New York Times,
vulnerability,
web,
website,
White Hat,
XSS
Saturday, 6 June 2015
CVE-2014-8753 Cit-e-Net Multiple XSS (Cross-Site Scripting) Web Security Vulnerabilities
Exploit Title: Cit-e-Net Multiple XSS (Cross-Site Scripting) Web Security Vulnerabilities
Product: Cit-e-Access
Vendor: Cit-e-Net
Vulnerable Versions: Version 6
Tested Version: Version 6
Advisory Publication: February 12, 2015
Latest Update: June 01, 2015
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference: CVE-2014-8753
Impact CVSS Severity (version 2.0):
CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6
CVSS Version 2 Metrics:
Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism
Access Complexity: Medium
Authentication: Not required to exploit
Impact Type: Allows unauthorized modification
Discover and Author: Jing Wang [School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore] (@justqdjing)
Instruction Details:
(1) Vendor & Product Description:
Vendor:
Cit-e-Net
Product & Version:
Cit-e-Access
Version 6
Vendor URL & Download:
Cit-e-Net can be downloaded from here,
Product Introduction:
"We
are a premier provider of Internet-based solutions encompassing web
site development and modular interactive e-government applications which
bring local government, residents and community businesses together.
Cit-e-Net
provides a suite of on-line interactive services to counties,
municipalities, and other government agencies, that they in turn can
offer to their constituents. The municipal government achieves a greater
degree of efficiency and timeliness in conducting the daily operations
of government, while residents receive improved and easier access to
city hall through the on-line access to government services.
Our web-based applications can help your municipality to acheive its e-government goals. Type & click website content-management empowers the municipality to manage the website quickly and easily. Web page styles & formats are customizable by the municipality, and because the foundation is a database application, user security can be set for individual personnel and module applications. Our application modules can either be integrated into your existing municipal web site or implemented as a complete web site solution. It's your choice! Please contact us at info@cit-e.net to view a demonstration of our municipal web site solution if you are an elected official or member of municipal management and your municipality is looking for a cost efficient method for enhancing & improving municipal services.
Interactive Applications
Online Service Requests
Online Tax Payments by ACH electronic-check or credit card.
Online Utility Payments by ACH electronic-check or credit card.
Online General-Payments by ACH electronic-check or credit card.
Submit Volunteer Resume's Online for the municipality to match your skills with available openings."
(2) Vulnerability Details:
Cit-e-Access web
application has a security bug problem. It can be exploited by XSS
attacks. This may allow a remote attacker to create a specially crafted
request that would execute arbitrary script code in a user's browser
session within the trust relationship between their browser and the
server.
Several
similar products 0Day vulnerabilities have been found by some other bug
hunter researchers before. Cit-i-Access has patched some of them. Open
Sourced Vulnerability Database (OSVDB) is an independent and
open-sourced database. The goal of the project is to provide accurate,
detailed, current, and unbiased technical information on security
vulnerabilities. The project promotes greater, open collaboration
between companies and individuals. It has published suggestions,
advisories, solutions details related to important vulnerabilities and
cyber intelligence.
(2.1) The first programming code flaw occurs at "/eventscalendar/index.cfm?" page with "&DID" parameter in HTTP GET.
(2.2) The second programming code flaw occurs at "/search/index.cfm?" page with "&keyword" parameter in HTTP POST.
(2.3) The third programming code flaw occurs at "/news/index.cfm" page with "&jump2" "&DID" parameter in HTTP GET.
(2.4) The fourth programming code flaw occurs at "eventscalendar?" page with "&TPID" parameter in HTTP GET.
(2.5) The fifth programming code flaw occurs at "/meetings/index.cfm?" page with "&DID" parameter in HTTP GET.
(3) Solutions:
Leave message to vendor. No response.
References:
Labels:
0day Exploit,
2014-8753,
Cit-e-Net,
computer bug,
Cross-Site Scripting,
cve,
cyber security,
Internet Testing,
IT News,
justqdjing,
Vulnerabilities,
Wang.Jing,
web application,
Whitehat Report,
XSS
Friday, 5 June 2015
CNN Travel.cnn.com XSS and Ads.cnn.com Open Redirect Web Security Vulnerabilities
Domain:
http://cnn.com
"The Cable News Network (CNN) is an American basic cable and satellite television channel that is owned by the Turner Broadcasting System division of Time Warner. The 24-hour cable news channel was founded in 1980 by American media proprietor Ted Turner. Upon its launch, CNN was the first television channel to provide 24-hour news coverage, and was the first all-news television channel in the United States. While the news channel has numerous affiliates, CNN primarily broadcasts from the Time Warner Center in New York City, and studios in Washington, D.C. and Los Angeles, its headquarters at the CNN Center in Atlanta is only used for weekend programming. CNN is sometimes referred to as CNN/U.S. to distinguish the American channel from its international sister network, CNN International. As of August 2010, CNN is available in over 100 million U.S. households. Broadcast coverage of the U.S. channel extends to over 890,000 American hotel rooms, as well as carriage on cable and satellite providers throughout Canada. Globally, CNN programming airs through CNN International, which can be seen by viewers in over 212 countries and territories. As of February 2015, CNN is available to approximately 96,289,000 cable, satellite and, telco television households (82.7% of households with at least one television set) in the United States." (Wikipedia)
Discovered and Reported by:
Jing Wang, Division of Mathematical Sciences (MAS), School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore. (@justqdjing)
Vulnerability Description:
CNN has a cyber security bug problem. It cab be exploited by XSS (Cross Site Scripting) and Open Redirect (Unvalidated Redirects and Forwards) attacks.
Based on news published, CNN users were hacked based on both Open Redirect and XSS vulnerabilities.
According to E Hacker News on June 06, 2013, (@BreakTheSec) came across a diet spam campaign that leverages the open redirect vulnerability in one of the top News organization CNN.
After the attack, CNN takes measures to detect Open Redirect vulnerabilities. The measure is quite good during the tests. Almost no links are vulnerable to Open Redirect attack on CNN's website, now. It takes long time to find a new Open Redirect vulnerability that is un-patched on its website.
CNN.com was hacked by Open Redirect in 2013. While the XSS attacks happened in 2007.
<1> "The tweet apparently shows cyber criminals managed to leverage the open redirect security flaw in the CNN to redirect twitter users to the Diet spam websites."
Figure from ehackingnews.com
At the same time, the cybercriminals have also leveraged a similar vulnerability in a Yahoo domain to trick users into thinking that the links point to a trusted website.
Yahoo Open Redirects Vulnerabilities:
<2> CNN.com XSS hacked
Several other similar products 0-day vulnerabilities have been found by some other bug hunter researchers before. CNN has patched some of them. BugTraq is a full disclosure moderated mailing list for the *detailed* discussion and announcement of computer security vulnerabilities: what they are, how to exploit them, and how to fix them. The below things be posted to the Bugtraq list: (a) Information on computer or network related security vulnerabilities (UNIX, Windows NT, or any other). (b) Exploit programs, scripts or detailed processes about the above. (c) Patches, workarounds, fixes. (d) Announcements, advisories or warnings. (e) Ideas, future plans or current works dealing with computer/network security. (f) Information material regarding vendor contacts and procedures. (g) Individual experiences in dealing with above vendors or security organizations. (h) Incident advisories or informational reporting. (i) New or updated security tools. A large number of the fllowing web securities have been published here, Buffer overflow, HTTP Response Splitting (CRLF), CMD Injection, SQL injection, Phishing, Cross-site scripting, CSRF, Cyber-attack, Unvalidated Redirects and Forwards, Information Leakage, Denial of Service, File Inclusion, Weak Encryption, Privilege Escalation, Directory Traversal, HTML Injection, Spam. It also publishes suggestions, advisories, solutions details related to XSS and URL Redirection vulnerabilities and cyber intelligence recommendations.
(1) CNN (cnn.com) Travel-City Related Links XSS (cross site scripting) Web Security Bugs
Domain:
travel.cnn.com/
Vulnerability Description:
The programming bug flaws occur at "/city/ all" pages. All links under this URL are vulnerable to XSS attacks, e.g
XSS may allow a remote attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server. Base on Acunetix, exploited XSS is commonly used to achieve the following malicious results
- Identity theft
- Accessing sensitive or restricted information
- Gaining free access to otherwise paid for content
- Spying on user’s web browsing habits
- Altering browser functionality
- Public defamation of an individual or corporation
- Web application defacement
- Denial of Service attacks
The code programming flaw can be exploited without user login. Tests were performed on Firefox (34.0) in Ubuntu (14.04) and IE (9.0.15) in Windows 7.
PoC:
http://travel.cnn.com/city/ all/all/tokyo/all' /"><img src=x onerror=prompt(/justqdjing/)>
http://travel.cnn.com/city/ all/all/bangkok/all' /"><img src=x onerror=prompt(/justqdjing/)>
(1.1) Poc Video:
(2) CNN cnn.com ADS Open Redirect Web Security Bug
Domain:
ads.cnn.com
Vulnerability Description:
The programming code flaw occurs at "event.ng" page with "&Redirect" parameter, i.e.
From OWASP, an open redirect is an application that takes a parameter and redirects a user to the parameter value without any validation. This vulnerability is used in phishing attacks to get users to visit malicious sites without realizing it. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing. Such attacks are useful as the crafted URL initially appear to be a web page of a trusted site. This could be leveraged to direct an unsuspecting user to a web page containing attacks that target client side software such as a web browser or document rendering programs.
The vulnerabilities can be attacked without user login. Tests were performed on Microsoft IE (10.0.9200.16750) of Windows 8, Mozilla Firefox (34.0) & Google Chromium 39.0.2171.65-0 ubuntu0.14.04.1.1064 (64-bit) of Ubuntu (14.04),Apple Safari 6.1.6 of Mac OS X Lion 10.7.
(2.1) Use the following tests to illustrate the scenario painted above.
The redirected webpage address is "http://webcabinet.tumblr.com/". Suppose that this webpage is malicious.
Vulnerable URL:
POC:
http://ads.cnn.com/event.ng/ Type=click&FlightID=92160& AdID=125504&TargetID=1346& RawValues=&Redirect=http:%2f% 2fwebcabinet.tumblr.com
Since CNN is well-known worldwide, this vulnerability can be used to do "Covert Redirect" attacks to other websites.
(2.1) Poc Video:
Those vulnerabilities were reported to CNN in early July by Contact from Here. But they are still not been patched yet.
More Details:
Labels:
0day Exploit,
Ads.cnn.com,
CNN,
Computer Science,
cyber intelligence,
Hack Train,
Interent Flaw,
IT News,
justqdjing,
Open Redirect,
Security Vulnerability,
Travel.cnn.com,
URF,
Wang.Jing,
Website Testing,
XSS
Subscribe to:
Posts (Atom)








